|
|
| |
|
| |
Cherokee: format string vulnerability
| Package(s): | cherokee |
CVE #(s): | |
| Created: | November 1, 2004 |
Updated: | November 3, 2004 |
| Description: |
Florian Schilhabel from the Gentoo Linux Security Audit Team found a
format string vulnerability in the cherokee_logger_ncsa_write_string()
function. Using a specially crafted URL when authenticating via auth_pam,
a malicious user may be able to crash the server or execute arbitrary code
on the target machine with permissions of the user running Cherokee. |
| Alerts: |
|
( Log in to post comments)
|
|
|